Ward, Mike S wrote:

Hello all, I have a small problem and I don't know how to handle it at
this point. I initialized a CKDS and a PKDS on our old z800 using the
pass phrase method. The z800 had ccf processors. I want to bring these
datasets into our z890 environment, but I don't exactly know how to do
it. The icsf book gives a good rendition on changing master keys, but
I'm doing that. I think what I need to do is use the z800 pass phrase to
initialize the crypto processors without initializing the pkds or ckds.
This would be like taking these datasets to a disaster recovery site and
utilizing them there. Do any of you have experience in doing this and if
so would you mind sharing what I need to do?

I assume, you have your pass phrase recorded (you remember it).
Just repeat the initialization process on z/890 using same method, same pass phrase but different (blank new) KDS datasets. Then you can stop ICSF and replace the datasets with your original ones (those from z/800). Then start ICSF. It should work, otherwise you still have valid KDSes.

It is not the only method.


BTW: If you don't have defined any keys in your CKDS/PKDS then you can initialize cryptography using any pass phrase and use those new KDSes.

Caution: CKDS initialized on z/890 system cannot be used on downlevel (z/800 or G6) system. The opposite direction is OK.


HTH
--
Radoslaw Skorupka
Lodz, Poland

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

Reply via email to